google-surf-mcp-search

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core search-and-extract capability matches the stated purpose, and installation is via standard npm/GitHub channels rather than obvious malware delivery. However, the skill’s footprint is broader than necessary because it supports arbitrary URL fetching, optional private-IP access, TLS bypass, and no-sandbox operation; combined with external-content ingestion, this creates meaningful SSRF and prompt-injection risk. Publisher/repo ownership mismatch adds trust uncertainty, but there is not enough evidence here to call it malicious.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 17, 2026, 04:52 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fgoogle-surf-mcp-search%2F@120ddc7bef5765af04245e8dcd0649741da4c810
Security Audit — socket — google-surf-mcp-search